CVE-2026-4901: Hydrosystem.poznan Control System
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in AlanWeb SCADA version 9.8.5
Affected products
- Hydrosystem.poznan Control System: before 9.8.5 (fixed in 9.8.5)
Published 2026-04-09. Last modified 2026-08-13.